data:image/s3,"s3://crabby-images/3c84a/3c84af5bd2a5459394e41b477bf8f0923dc29c27" alt="FireBrick FB6402 Скачать руководство пользователя страница 97"
Tunnels
80
• ESP encapsulation using HMAC-SHA1 authentication and AES-CBC encryption
• Authentication key 0123456789012345678901234567890123456789
• Encryption key 00010203040506070809101112131415
• Incoming SPI 1000, Outgoing SPI 2000
• FireBrick is providing connectivity for a local user subnet 10.1.1.0/24
• Linux system is providing connectivity for a local user subnet 10.2.2.0/24
A suitable FireBrick xml config for this would be:
<ipsec-ike>
<manually-keyed name = "Linux Manual"
local-ip="192.168.1.1" peer-ips="192.168.2.2"
local-spi="1000" remote-spi="2000" type="ESP"
auth-algorithm="HMAC-SHA1"
auth-key="0123456789012345678901234567890123456789"
crypt-algorithm="AES-CBC"
crypt-key="00010203040506070809101112131415"
routes="10.2.2.0/24" />
</ipsec-ike>
A corresponding ipsec-tools config file would be:
flush;
spdflush;
add 192.168.2.2 192.168.1.1 esp 1000 -m tunnel
-E rijndael-cbc 0x00010203040506070809101112131415
-A hmac-sha1 0x0123456789012345678901234567890123456789;
add 192.168.1.1 192.168.2.2 esp 2000 -m tunnel
-E rijndael-cbc 0x00010203040506070809101112131415
-A hmac-sha1 0x0123456789012345678901234567890123456789;
spdadd 10.1.1.0/24 10.2.2.0/24 any
-P in ipsec esp/tunnel/192.168.1.1-192.168.2.2/require;
spdadd 10.2.2.0/24 10.1.1.0/24 any
-P out ipsec esp/tunnel/192.168.2.2-192.168.1.1/require;
Note that rijndael is the name used by ipsec-tools for the AES algorithm.
11.2. FB105 tunnels
The FB105 tunnelling protocol is a FireBrick proprietary protocol that was first implemented in the FireBrick
FB105 device, and is popular with FB105 users for setting up VPNs etc. It is 'lightweight' in as much as it
is relatively simple, with low overhead and easy setup, but it does not currently offer encryption. Although
encryption is not available, the protocol does digitally sign packets, so that tunnel end-points can be confident
that the traffic originated from another 'trusted' end-point. Where it matters, encryption can be utilised via secure
protocols such as HTTPS or SSH over the tunnel.
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......